Total
17797 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-53438 | 1 Churchcrm | 1 Churchcrm | 2025-03-28 | N/A | 9.8 CRITICAL |
| EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute arbitrary SQL commands. | |||||
| CVE-2024-55104 | 1 Phpgurukul | 1 Online Nurse Hiring System | 2025-03-28 | N/A | 7.2 HIGH |
| Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin/add-nurse.php via the gender and emailid parameters. | |||||
| CVE-2024-55103 | 1 Phpgurukul | 1 Online Nurse Hiring System | 2025-03-28 | N/A | 7.2 HIGH |
| Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.php via the fullname parameter. | |||||
| CVE-2023-22324 | 1 Contec | 1 Conprosys Hmi System | 2025-03-28 | N/A | 6.5 MEDIUM |
| SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbitrary SQL command. As a result, information stored in the database may be obtained. | |||||
| CVE-2022-44298 | 1 Sscms | 1 Siteserver Cms | 2025-03-28 | N/A | 9.8 CRITICAL |
| SiteServer CMS 7.1.3 is vulnerable to SQL Injection. | |||||
| CVE-2024-27746 | 1 Mayurik | 1 Petrol Pump Management | 2025-03-28 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component. | |||||
| CVE-2023-49546 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | N/A | 8.8 HIGH |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php. | |||||
| CVE-2023-49547 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | N/A | 9.8 CRITICAL |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login. | |||||
| CVE-2023-49548 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | N/A | 8.8 HIGH |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user. | |||||
| CVE-2023-49968 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | N/A | 7.3 HIGH |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/manage_department.php. | |||||
| CVE-2023-49969 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | N/A | 4.3 MEDIUM |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer. | |||||
| CVE-2023-49970 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | N/A | 9.8 CRITICAL |
| Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=save_ticket. | |||||
| CVE-2023-49544 | 1 Oretnom23 | 1 Customer Support System | 2025-03-28 | N/A | 4.9 MEDIUM |
| A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php. | |||||
| CVE-2024-28613 | 1 Mayurik | 1 Php Task Management System | 2025-03-27 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in PHP Task Management System v.1.0 allows a remote attacker to escalate privileges and obtain sensitive information via the task_id parameter of the task-details.php, and edit-task.php component. | |||||
| CVE-2024-25248 | 1 Niushop | 1 B2b2c Multi-business | 2025-03-27 | N/A | 9.8 CRITICAL |
| SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via the order_id parameter. | |||||
| CVE-2023-23331 | 1 Amano | 1 Xoffice | 2025-03-27 | N/A | 9.8 CRITICAL |
| Amano Xoffice parking solutions 7.1.3879 is vulnerable to SQL Injection. | |||||
| CVE-2024-28558 | 1 Mayurik | 1 Petrol Pump Management | 2025-03-27 | N/A | 8.8 HIGH |
| SQL Injection vulnerability in sourcecodester Petrol pump management software v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to admin/app/web_crud.php. | |||||
| CVE-2024-25217 | 1 Oretnom23 | 1 Online Medicine Ordering System | 2025-03-27 | N/A | 9.8 CRITICAL |
| Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/view_product. | |||||
| CVE-2024-24105 | 1 Carmelo | 1 Computer Science Time Table System | 2025-03-27 | N/A | 7.8 HIGH |
| SQL Injection vulnerability in Code-projects Computer Science Time Table System 1.0 allows attackers to run arbitrary code via adminFormvalidation.php. | |||||
| CVE-2022-45297 | 1 Eq Project | 1 Eq | 2025-03-27 | N/A | 9.8 CRITICAL |
| EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter. | |||||
